Skip to main content

JWT decoder and verifier

Paste a token to see its header and claims. Add the secret or public key to check that its signature is genuine.

Decoding and verification use your browser's WebCrypto. A valid signature proves who signed the token — not that it should be accepted: still check the audience, issuer and expiry.

These tools run entirely in your browser. Nothing you paste or drop is uploaded, stored, or sent to analytics.

Three base64url segments separated by dots. A pasted "Bearer" prefix is ignored.

An HMAC secret for HS256–HS512; a -----BEGIN PUBLIC KEY----- PEM, a JWK or a JWKS for RSA and EC algorithms.

Paste a token to decode it.